CVE-2023-27372 is a critical remote code execution (RCE) vulnerability affecting SPIP versions prior to 4.2.1, including specific Debian packages. This flaw, rated 9.8 CVSS, stems from improper handling of serialization in public-facing forms, allowing unauthenticated attackers to execute arbitrary code with low attack complexity. While not yet on CISA's KEV list, readily available exploit modules for Metasploit and Nuclei, along with an ExploitDB entry, indicate a high likelihood of exploitation. Despite its critical nature and exploit availability, there is currently no significant public discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.18CPE matchmatch criteria | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.10CPE matchmatch criteria | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.8CPE matchmatch criteria | cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:spip:spip:4.2.0:-:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:spip:spip:4.2.0:alpha:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.